started · updated
SAP patches critical 10.0 severity vulnerability in Commerce Cloud
SAP has released critical security patches to address a maximum-severity vulnerability in its Commerce Cloud platform. The flaw, identified as CVE-2026-58231, has received a CVSS score of 10.0.
The vulnerability resides in the Data Hub Adapter, which serves as the integration layer between the storefront and backend systems such as ERP and product catalogs. Due to insufficient authorization checks and inadequate input validation, unauthenticated attackers can exploit the component to execute arbitrary code. Successful exploitation could lead to full control over the commerce platform, compromising the confidentiality, integrity, and availability of the application.
As a temporary mitigation, security experts suggest using IP filters to restrict access to the vulnerable endpoint. However, SAP advises customers to update to a corrected version of Commerce Cloud and perform a full redeployment.
In addition to this critical flaw, SAP’s August security updates also addressed other high-severity vulnerabilities, including a code injection flaw in Manufacturing Integration and Intelligence (CVE-2026-44772) and a memory corruption issue in the ABAP Application Server (CVE-2026-34265).